The Adaptation Gap as a Potential New Measure of Cyber Resilience in a World Where Capabilities Evolve Faster Than Strategic Cycles
Author’s research article | August 2026
When a market report forecasts the Threat Intelligence sector through to 2032, the first reaction is usually to focus on market size: USD 11.4 billion in 2025, rising to USD 33.2 billion by 2032, at a CAGR of 16.5%.[1] Yet a second question may be more important than the projection itself: how much confidence can we place in a long-term forecast in a field where the capabilities of the underlying technology are changing within periods measured in months?
The year 2032 is not a known technological deadline, nor a milestone imposed on the industry by any external authority. In the report concerned, it is simply the methodological horizon selected by the research publisher. Such multi-year periods make sense in market modelling because they enable estimates of investment, revenues and demand scenarios. The difficulty arises when a commercial projection gradually begins to be interpreted as a map of the technological future. In an AI and cyber environment, that substitution is becoming increasingly risky, because there is no guarantee that the categories, relationships and technical assumptions that apply today will retain the same meaning seven years from now.

When the Subject of the Forecast Changes Faster Than the Forecasting Cycle
Most importantly, there is already an empirical basis for this argument. The Stanford Institute for Human-Centered Artificial Intelligence, in its AI Index Report 2026, records that frontier models improved by approximately thirty percentage points on the Humanity’s Last Exam benchmark in just one year, while tests designed to remain challenging for years are becoming saturated within a matter of months.[2] This is more than an indicator of model progress. It is a signal that the useful lifespan of the instruments we use to measure progress is shortening to such an extent that the benchmarks themselves are becoming part of an accelerated cycle of obsolescence.
METR approaches the problem from another angle. Rather than relying on conventional benchmark scores, its researchers measure the length of task an AI agent can reliably complete autonomously compared with the time a human would require to perform the same task. Their analysis indicates approximately exponential growth in the so-called task-completion time horizon, with a historical doubling time of roughly seven months across the observed set of software tasks.[3] METR is careful to emphasise the limitations of extrapolation, which is methodologically important: a trend is not a prophecy. Yet the fact that measurable autonomy is changing on a cycle of only a few months is sufficient to raise a serious question about planning that assumes multi-year stability in technological capabilities.
Precision is essential here. Current LLM systems do not “self-develop” in the sense of uncontrolled, independent training without human involvement. What is genuinely changing is the amount of human intervention required between defining an objective and executing it. Contemporary agentic systems can plan multiple steps, use tools, write and execute code, verify outputs and repeat the process. Human involvement is therefore shifting from executing every individual action towards defining goals, boundaries and criteria, and performing verification. That shift simultaneously increases productivity and increases the cost of poor judgement, weak controls or the erosion of human competence.
Offensive Capability Operates on a Shorter Cycle Than Organisational Change
Cyber security makes this problem substantially more acute because an attacker does not have to wait for a new strategy, a new budget year or a regulatory cycle. The UK National Cyber Security Centre assesses that AI will almost certainly make elements of cyber intrusion more effective and broaden access to offensive capabilities among a wider range of state and non-state actors. It specifically warns that the time between disclosure of a vulnerability and its exploitation has already fallen to days, and that AI will almost certainly reduce that window further.[4]
This brings us to the core problem. Organisations frequently operate with annual strategic reviews, quarterly committees, monthly cycles for certain operational controls, and procurement procedures that can take even longer. Offensive techniques, exploit tools, phishing patterns or the abuse of a newly released AI service can spread much more rapidly. The ENISA Threat Landscape 2025 describes how the popularity of generative AI is already being exploited for malware distribution, how machine-learning models and packages are being targeted, and how attacks are emerging against the configuration of AI coding assistants.[5] When the diffusion time of a new capability is shorter than the time an organisation requires to understand it and change its behaviour, a form of strategic exposure emerges that a conventional maturity score may fail to detect entirely.

The Adaptation Gap: From an Intuitive Idea to a Measurable Variable
This creates space for a concept that merits much more serious development: the adaptation gap, meaning the gap between the speed of threat evolution and the speed of organisational adaptation. It is not currently a standardised international metric and should not be presented as one. Its value lies precisely in its potential to translate an abstract discussion about the “speed of change” into something observable and measurable.
At its simplest, one side of the relationship would represent the time required for a new threat capability to become operationally relevant — from the disclosure of a vulnerability, the emergence of a new model or technique, to its actual use. The other side would represent the time an organisation requires to identify the signal, understand its business context, make a decision, modify architecture or controls, train its people and confirm that the change actually works. The relationship between these two periods could be expressed as:
Organisational Adaptation Time / Threat Capability Diffusion Time
When the ratio is greater than one, the organisation is adapting more slowly than the threat is becoming operational. The higher the ratio, the wider the window of exposure.
Such a model would not have to remain theoretical. It is already possible to measure the time from an intelligence signal to assessment, from assessment to decision, and from decision to implementation; the time required to patch a critical vulnerability; the time needed to change an access policy, assess a new supplier, activate alternative infrastructure or conduct a recovery exercise. ENISA NIS Investments 2025 already collects data on patching times, supply-chain risk-management practices, cyber staffing, the challenges of implementing NIS2 and preparedness for different scenarios, demonstrating that the European institutional framework already holds a substantial proportion of the data required for a more rigorous measurement of adaptation speed.[6]
The adaptation gap could therefore become a link between Threat Intelligence and cyber resilience. Intelligence tells us what has changed externally; adaptation time shows how long the organisation needs to change internally. Only when these two timeframes are considered together can we begin to measure whether our defence is genuinely keeping pace with the environment, or merely maintaining a formally acceptable state that is becoming progressively older relative to the threat.
Cyber Resilience as a Response to the Limits of Prediction
This is where NIST’s definition of cyber resiliency takes on particular contemporary relevance. NIST SP 800-160 Vol. 2 does not begin from the assumption that an organisation will perfectly predict the next attack. Instead, it structures cyber resiliency around four capabilities: anticipate, withstand, recover and adapt.[7]
The final term — adapt — becomes critical in an environment in which assumptions change faster than multi-year plans. Resilience is not evidence that forecasting has failed; it is an architecture designed around the recognition that forecasting will inevitably remain incomplete.
Long-term planning should therefore not be abandoned. On the contrary, infrastructure, workforce development, education systems, regulatory frameworks, technological sovereignty and capital investment all require multi-year horizons. What should be abandoned is false precision: the assumption that today’s products and categories allow us to draw a detailed technical map of cyber defence in 2032.
A long-term cyber strategy should define what must remain stable regardless of a particular model or tool — critical business functions, acceptable risk, identities, data, recovery objectives, architectural redundancy, supplier dependencies and accountability — while technical assumptions are reassessed at far shorter intervals.
The Human Factor: Who Controls a System That Is Doing Increasingly More by Itself?
AI acceleration creates another adaptation gap, this time between the capabilities of the tools and the capabilities of the people expected to supervise them. The OECD Digital Education Outlook 2026 warns that improved performance with GenAI does not automatically translate into improved learning. Offloading cognitive tasks to a general-purpose chatbot can increase performance without producing durable knowledge acquisition, and in some studies the advantage disappears once the tool is removed.[8]
This problem transfers directly into the professional environment. If an analyst becomes faster because of AI, while at the same time independently conducting fewer assessments, verifying fewer sources or developing less understanding of the underlying technical problem, productivity can grow faster than expertise.
The World Economic Forum’s Global Cybersecurity Outlook 2026 reports that 77% of organisations are already using AI in cyber security, while 54% identify insufficient knowledge and skills as a principal obstacle, 41% cite the need for human oversight, and 39% point to uncertainty surrounding risk.[9] This is an important empirical signal that technology adoption and organisational capability are not the same thing.
An organisation can purchase or activate a new AI capability very quickly. Building the competence required to use it safely, challenge its outputs and maintain meaningful control over it remains a slower process.
The European Adaptation Gap: From Individual Companies to the Wider Ecosystem
The same principle can be extended from the level of an individual company to the European cyber ecosystem as a whole. The European Cybersecurity Competence Centre and the network of 27 National Coordination Centres were established to connect Member States, industry, academia and the research community, strengthen European cyber capabilities and facilitate the participation of SMEs and start-ups in joint projects.[10]
In July 2026, the European Commission further connected AI and cyber security through a dedicated Action Plan, explicitly recognising that AI can simultaneously enhance detection and protection while enabling the automation of attacks and operations at unprecedented speed and scale.[11]
In this context, the relevant question is not merely how many funds, regulations, centres and programmes Europe has, but how rapidly that system converts new knowledge into collective capability.
If ENISA identifies a new pattern, the research community confirms the risk, and attackers operationalise it within a few weeks, how long does it take for guidance, funding, procurement, training and implementation to reach the SME that forms part of a critical supply chain?
That period represents the European version of the adaptation gap. The longer it becomes, the more institutional sophistication can paradoxically coexist with real operational exposure on the ground.
What, Then, Should We Do with a Forecast to 2032?
Long-term forecasts retain value, but we need to define their purpose more precisely. A forecast to 2032 can help estimate market demand, investment directions, workforce requirements, infrastructure needs and regulatory scenarios. It should not be interpreted as evidence that we already understand the architecture of cyber defence, the dominant AI models or the operating methods of threat actors in that year.
The faster technological development becomes, the more the strategic horizon must be anchored in capabilities that remain resilient to changes in products rather than in the products themselves.
Modern cyber strategy must therefore be both long-term and extremely short-term.
Over the long term, we define what must survive: critical functions, trust, data, minimum operational capacity, alternative suppliers, recovery capability and accountability.
Over the short term, we continuously reassess our assumptions: what new models can do, how offensive techniques are changing, what dependencies we have just created, and where our response has become slower than the threat.
Strategy is no longer merely a document that is updated periodically. It becomes a closed intelligence–decision–adaptation loop.
This is why the adaptation gap could prove more valuable than another static maturity score. Maturity tells us where an organisation stands at a particular moment. Adaptation speed tells us how quickly that organisation will cease to be mature once its environment changes.
In an era of AI acceleration, this distinction becomes decisive.
It is no longer enough to be well protected against yesterday’s threat model. An organisation must know how long it takes to recognise that the model has changed — and how long it takes to change itself in response.
The year 2032 is therefore neither a “dead end” nor a date beyond which present development somehow ceases. It is more useful to view it as the boundary of a statistical window and as a test of our methodology.
If AI capabilities, benchmarks and offensive techniques are changing on cycles of only a few months, the greatest strategic error would be to seek certainty through increasingly precise predictions about a distant technological future. A better response is to build systems capable of anticipating what can be seen, withstanding what was not predicted, recovering critical functions, and adapting quickly enough to ensure that the same weakness does not remain exposed.
In the next phase of cyber security, the advantage may not belong to the organisation that most accurately predicted what 2032 would look like.
It may belong to the organisation that is fastest to recognise that the assumption underpinning yesterday’s strategy can no longer be treated as true.
If we can measure that speed, the adaptation gap ceases to be a metaphor and becomes a potential new instrument of cyber strategy and cyber resilience.
References and Sources
[1] Research and Markets / Market Glass, Inc. Threat Intelligence – Global Strategic Business Report. 2026. Source: https://www.researchandmarkets.com/reports/4806357/threat-intelligence-global-strategic-business Forecast period 2025–2032; market estimate USD 11.4 billion → USD 33.2 billion.
[2] Stanford Institute for Human-Centered Artificial Intelligence. Technical Performance, The 2026 AI Index Report. 2026. Source: https://hai.stanford.edu/ai-index/2026-ai-index-report/technical-performance Frontier models improved by approximately 30 percentage points on Humanity’s Last Exam within one year; benchmarks are becoming saturated within months.
[3] METR. Measuring AI Ability to Complete Long Tasks. 2025. Source: https://metr.org/blog/2025-03-19-measuring-ai-ability-to-complete-long-tasks/ Task-completion time-horizon methodology and an empirical historical trend of approximate doubling every seven months across the observed task set.
[4] UK National Cyber Security Centre (NCSC). Impact of AI on Cyber Threat from Now to 2027. 2025. Source: https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027 AI and the shrinking interval between vulnerability disclosure and exploitation; expansion of AI-enabled intrusion capabilities.
[5] ENISA. ENISA Threat Landscape 2025. 2025. Source: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025 AI-enabled threats, fraudulent AI tools, supply-chain risks and LLM-related risks.
[6] ENISA. NIS Investments 2025. 2025. Source: https://www.enisa.europa.eu/publications/nis-investments-2025 EU data concerning resources, skills, patching, supply-chain management and organisational preparedness.
[7] NIST. SP 800-160 Vol. 2 Rev. 1: Developing Cyber-Resilient Systems. 2021. Source: https://csrc.nist.gov/pubs/sp/800/160/v2/r1/final The anticipate–withstand–recover–adapt framework.
[8] OECD. OECD Digital Education Outlook 2026: Exploring Effective Uses of Generative AI in Education. 2026. Source: https://doi.org/10.1787/062a7394-en GenAI, cognitive offloading, learning outcomes and the need for approaches centred on developing human capabilities.
[9] World Economic Forum / Accenture. Global Cybersecurity Outlook 2026. 2026. Source: https://www.weforum.org/publications/global-cybersecurity-outlook-2026/ AI adoption, the skills gap, human oversight and cyber inequality.
[10] European Cybersecurity Competence Centre (ECCC). National Coordination Centres. 2026. Source: https://cybersecurity-centre.europa.eu/nccs-0_en Network of 27 NCCs linking industry, research and the SME sector.
[11] European Commission. EU Action Plan on Cybersecurity and Artificial Intelligence. 2026. Source: https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence Coordinated EU approach to AI capabilities, cyber risk, resilience and technological sovereignty.
Author’s note on the proposed concept: The term “adaptation gap” is used in this article as a proposed analytical framework rather than as an existing international standard. The proposed ratio of Organisational Adaptation Time / Threat Capability Diffusion Time requires further empirical validation, definition of appropriate indicators, and testing against organisational and sector-level data.
Originally published by Advanced Cyber Security on 10 September 2026. Read this article on LinkedIn ↗.




